Aqua Star: Ninth Circuit applies Authorized Entry Exclusion to Social Engineering Fraud Claim

On April 17, 2018, the Ninth Circuit Court of Appeals released its decision in Aqua Star (USA) Corp. v. Travelers Casualty and Surety Company of America, affirming the decision of the U.S. District Court for the Western District of Washington (see our July 19, 2016 post).  The decision offers guidance to fidelity insurers with respect to the application of the “authorized entry” exclusion found in the base wording of many commercial crime policies (sometimes referred to as the “authorized access” exclusion), and illustrates how this exclusion may operate in the context of a social engineering fraud loss.

 


The Facts

The insured, Aqua Star (USA) Corp. (“Aqua Star”), is a seafood importer that had a pre-existing relationship with a legitimate vendor, Longwei.  In the summer of 2013, Longwei’s computer system was hacked.  The hacker apparently monitored email exchanges between an Aqua Star employee and a Longwei employee before intercepting those email exchanges and using a “spoof” email domain to send fraudulent emails to the Aqua Star employee.  In the spoofed emails, the hacker directed the Aqua Star employee to change the bank account information Aqua Star had on record for Longwei for future wire transfer payments.

The Aqua Star employee inserted the revised banking information into Aqua Star’s computer system.  This revised information was then used to create wire instructions that were transmitted to Aqua Star’s bank, the Bank of America.  As a result, $713,890 was wired to the hacker’s account before the fraud came to light.

The Travelers Coverage

Aqua Star maintained a Wrap+ Crime Policy with Travelers.  The policy covered Aqua Star for its “direct loss of, or direct loss from damage to, Money, Securities, and Other Property directly caused by Computer Fraud”, as defined.  Travelers relied on Exclusion G to the policy, which provided that the policy:

will not apply to loss resulting directly or indirectly from the input of Electronic Data by a natural person having the authority to enter the Insured’s Computer System.

As a general observation, this type of exclusion is intended to reinforce the industry view that traditional commercial crime coverage is not intended to respond to social engineering fraud losses.  At present, social engineering fraud coverage is typically added to commercial crime policies by endorsement, with the endorsement providing that the exclusion in the base wording does not apply in respect of coverage afforded by the endorsement.  The intent is to reinforce that only social engineering fraud coverage, and not the traditional computer or funds transfer fraud coverages, responds to social engineering fraud losses.


The Decision

The District Court had granted Travelers’ summary judgment motion on the issue of whether Exclusion G applied to the loss.  The District Court rejected Aqua Star’s arguments that Exclusion G did not apply because: (i) Aqua Star had also entered data into the computer system of a third party, Bank of America; and, (ii) Exclusion G should be confined to circumstances in which a fraud is perpetrated by an authorized user of an insured’s computer system, such as an employee or legitimate customer.

In brief reasons, the Ninth Circuit affirmed the District Court’s grant of summary judgment, holding that:

Exclusion G unambiguously provides that the policy “will not apply to loss or damages resulting directly or indirectly from the input of Electronic Data by a natural person having the authority to enter the Insured’s Computer System….”  Aqua Star’s losses resulted from employees authorized to enter its computer system changing wiring information and sending four payments to a fraudster’s account.  These employees “ha[d] the authority to enter” Aqua Star’s system when they “input” Electronic Data, on Aqua Star computers, to change the wiring information and authorize the four wires.  Their conduct fits squarely within the Exclusion.  While other contractual exclusions may also bar coverage in this case, we need not go any further. 


Conclusion

The Ninth Circuit’s decision in Aqua Star provides a concise affirmation of the District Court’s detailed analysis of Exclusion G of the Travelers Wrap+ policy.  This case, along with numerous others such as Pestmaster (see our August 4, 2016 post) and InComm (see our March 22, 2017 post), reflects the intended boundary between social engineering fraud coverage and “traditional” computer fraud and funds transfer fraud coverages.  Courts have generally interpreted the computer fraud coverage as being intended to cover loss due to unauthorized hacking and payment instructions by third parties, not employees’ authorized entries of data or payment instructions induced by external fraud.

To address this perceived gap, insurers have introduced social engineering fraud endorsements to respond to the latter scenario.  Such coverage has been available in the United States since 2013 and in Canada since 2014.  The “authorized entry” exclusion reinforces the underwriting intent that the two coverages respond to different loss scenarios.  In our view, it is appropriate to keep this context in mind in assessing both the applicability of “authorized entry” exclusions and, more generally, the dividing line between social engineering fraud coverage and other coverages.

Aqua Star (USA) Corp. v. Travelers Casualty and Surety Company of America, 2018 WL 1804338 (9th Cir.)

Fidelity Blog

Gore, Kilpatrick & Dambrino PLLC: U.S. District Court finds No Social Engineering Fraud Coverage in Phony Debt Collection Fraud

On March 31, 2026 the U.S. District Court for the Northern District of Mississippi released its decision in Gore, Kilpatrick & Dambrino PLLC v. Spinnaker Ins. Co.  The Court interpreted the requirements of a Social Engineering Fraud (SEF) insuring agreement in a cyber policy in the context of a phony debt collection fraud perpetrated on … Continued

by

Westlake Chemical: Texas Court of Appeals applies Authorized Representative Exclusion in finding No Coverage under Crime Policy for Phony Invoicing Scheme

On May 25, 2023, the Texas Court of Appeals released its decision in Westlake Chemical Corporation v. Berkley Regional Insurance Company.  The Court affirmed the District Court’s summary judgment in favour of the insurers on the basis that the Authorized Representative Exclusion applied.  The Court’s decision is notable in finding that the exclusion does not require … Continued

by

Cachet Financial Services: U.S. District Court finds No Coverage under Commercial Crime Policy for Alleged ACH Kiting and Related Frauds

In the recent decision of Cachet Financial Services v. Berkley Insurance Company, the United States District Court for the Central District of California found no coverage under a commercial crime policy in respect of several alleged frauds involving a payroll processor. The decision is instructive for fidelity claims professionals as to the meaning of “alteration” in … Continued

by

Star Title Partners: Eleventh Circuit finds No Coverage for Social Engineering Fraud Loss under Cybercrime Endorsement to Cyber Protection Policy

On September 6, 2022, the Eleventh Circuit Court of Appeals released its decision in Star Title Partners of Palm Harbor, LLC v. Illinois Union Insurance Company.  In deciding that a social engineering fraud (SEF) loss did not fall within the coverage afforded under a Deceptive Transfer Fraud insuring clause, the Court construed the terms “employee,” “customer,” … Continued

by

Mississippi Silicon: Fifth Circuit finds No Coverage for Social Engineering Fraud Loss under Crime Policy’s Computer Fraud Coverage

On February 4, 2021, the Fifth Circuit Court of Appeals released its decision in Mississippi Silicon Holdings, LLC v. AXIS Insurance Company. In affirming the lower court’s grant of summary judgment in favour of AXIS, the Fifth Circuit made important findings regarding the proper scope of the Computer Fraud coverage; whether a fraudster’s opening of a … Continued

by

All Fidelity Blog Posts